CVE-2015-9543: Infoleak
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.newwebsocketclient in console/websocketproxy.py.
Other sources
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.newwebsocketclient in console/websocketproxy.py.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9543?
The severity of CVE-2015-9543 is low with a severity value of 3.3.
How does CVE-2015-9543 affect OpenStack Nova?
CVE-2015-9543 affects OpenStack Nova versions before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0.
What is the vulnerability in CVE-2015-9543?
The vulnerability in CVE-2015-9543 is the leakage of consoleauth tokens into log files, which can be exploited by an attacker with read access to obtain tokens used for console access.
Which setups of Nova are affected by CVE-2015-9543?
All Nova setups using novncproxy are affected by CVE-2015-9543.
How can I fix CVE-2015-9543?
To fix CVE-2015-9543, upgrade to OpenStack Nova version 18.2.4 or later, 19.1.0 or later, or 20.1.0 or later.